Irish%20Government%20launches%20insecure%20net%20security%20website%20Welcome%20to%20www.netsecure.ie,%20the%20new%20website%20set%20up%20by%20Dermot%20Ahern,%20Minster%20for%20Communication,%20Marine%20and%20Natural%20Resources%20and%20launched%20today%20(2%20July%202003)%20by%20Bertie%20Ahern,%20An%20Taoiseach.%20The%20site%20aims%20to%20provide%20''useful%20tips%20on%20how%20to%20make%20your%20computer%20a%20safer%20place,%20both%20in%20the%20workplace%20and%20at%20home''.%20An%20honourable%20initiative%20you%20will%20note%20that%20seeks%20to%20address%20the%20EU%20Council%20Resolution%20of%20January%2028th%202002%20that%20asked%20Member%20States%20to%20''launch%20or%20strengthen%20information%20and%20education%20campaigns%20to%20increase%20awareness%20of%20network%20and%20information%20security''.
%20Unfortunately%20the%20website%20does%20not%20set%20a%20very%20good%20example.%20See%20www.netsecure.ie%20is%20really%20not%20that%20secure.%20Sorry%20lads.
%20For%20starters,%20any%20visitor%20to%20the%20site%20can%20-%20through%20a%20clever,%20simple%20and%20TOTALLY%20overlooked%20trick%20-%20manage%20to%20doctor%20a%20URL%20and%20in%20so%20doing%20create%20a%20new%20page%20on%20the%20netsecure.ie%20website.%20What's%20more%20this%20oversight%20by%20the%20developers%20of%20the%20site%20means%20that%20ANYONE%20can%20create%20their%20own%20page%20creating%20a%20customised%20URL%20pointing%20to%20the%20www.netsecure.ie%20webserver%20(this%20page%20you%20are%20reading%20is%20an%20example).%20There's%20nothing%20then%20to%20stop%20such%20a%20person%20forwarding%20the%20customised%20URL%20on%20to%20others%20by%20email%20or%20using%20the%20URL%20to%20create%20a%20hyperlink%20on%20another%20HTML%20page%20that%20points%20to%20the%20customised%20page%20on%20the%20netsecure.ie%20website%20.%20To%20quote%20a%20certain%20Springfield%20resident,%20''Doh!''
%20Unfortunate%20for%20the%20government%20this%20basic%20oversight%20could%20be%20exploited%20in%20an%20extreme%20manner.%20For%20example,%20somebody%20could%20(using%20HTML's%20<img%20src=>%20tag)%20insert%20on%20this%20very%20page%20pornographic%20images%20hosted%20on%20another%20webserver.%20Alternatively%20one%20could%20be%20a%20bit%20less%20provocative%20and%20provide%20links%20to%20pages%20all%20sorts%20of%20WWW%20pages%20from%20which%20people%20are%20invited%20to%20download%20some%20dodgy%20spyware%20to%20install%20on%20their%20PC.%20For%20example%20one%20could%20provide%20a%20links%20to:
%20%20%20%20-
The%20%20%20%20%20Alexa%20toolbar%20(contains%20spyware%20agents%20whereby%20information%20about%20your%20%20%20%20%20web%20surfing%20is%20gathered%20for%20statistics%20purposes.%20Whether%20or%20not%20amazon.com,%20%20%20%20%20the%20owner%20of%20Alexa,%20does%20other%20things%20with%20this%20information%20is%20not%20known.)
%20%20%20- The%20Gator%20''eWallet''%20%20%20%20%20(Gator's%20''eWallet''%20accesses%20personal%20information,%20using%20your%20IP%20%20%20%20%20address,%20that%20it%20stores%20in%20an%20encrypted%20file%20on%20your%20PC.%20Gator%20also%20provides%20%20%20%20%20aggregate%20statistics%20about%20its%20''customers''%20traffic%20patterns%20and%20%20%20%20%20related%20site%20information%20to%20third-party%20vendors.)
%20
%20It%20is,%20of%20course,%20NOT%20recommended%20that%20anyone%20actually%20installs%20any%20such%20Spyware%20on%20their%20PC.%20But%20unfortunately%20such%20elementary%20and%20necessary%20privacy%20advice%20for%20Irish%20web%20surfers%20is%20not%20provided%20by%20the%20government%20on%20this%20website.%20Basically%20there%20is%20not%20A%20SINGLE%20WORD%20on%20spyware%20mentioned%20on%20this%20website%20nor%20about%20how%20it%20can%20compromise%20one's%20privacy%20when%20surfing%20the%20WWW.%20Most%20glaring%20is%20that%20there's%20no%20mention%20in%20the%2035%20page%20''Citizens%20Awareness%20Material'' document%20that%20the%20government%20offers%20for%20download%20on%20this%20site.%20Interestingly%20the%20Government%20appears%20to%20have%20engaged%20PriceWaterhouseCoopers%20to%20author%20this%20document.%20PWC%20do%20after%20all%20claim%20on%20one%20of%20their%20own%20webpages%20to%20be%20''a%20global%20leader%20in%20information%20security%20and%20privacy%20solutions''.%20Unfortunately%20such%20claims%20can%20only%20be%20called%20in%20to%20question%20when%20you%20see%20that%20they%20are%20prepared%20to%20put%20their%20name%20to%20a%20document%20that%20does%20not%20address%20Spyware%20-%20a%20key%20privacy%20issue%20for%20web%20surfers%20today%20- %20in%20even%20the%20slightest%20form%20.%20One%20trusts%20that%20PWC%20will%20kindly%20offer%20to%20refund%20to%20the%20Irish%20government%20at%20least%20part%20of%20any%20fee%20they%20may%20have%20received%20for%20the%20drafting%20of%20such%20an%20incomplete%20''Citizen%20Awareness''%20document.
%20Today%20the%20Minister%20for%20Communications%20stated%20that%20he%20wants%20Ireland%20to%20''lead%20the%20way%20in%20developing%20a%20culture%20and%20consciousness%20of%20security''. %20Unfortunately%20his%20own%20initiative%20of%20creating%20and%20launching%20the%20www.netsecure.ie%20website%20does%20not%20deliver%20the%20example%20one%20could%20rightly%20expect%20of%20our%20own%20government.%20It%20most%20definitely%20''does%20not%20lead%20the%20way.''
%20And%20speaking%20of%20leading%20the%20way%20I%20would%20like%20to%20take%20the%20opportunity%20to%20lead%20the%20way%20to%20my%20website,%20www.CLUAS.com,%20Ireland's%20No.%201%20alternative%20music%20webzine.%20CLUAS%20-%20lending%20an%20ear%20to%20the%20Irish%20Music%20Scene.%20Do%20check%20it%20out.%20And,%20no%20there%20is%20no%20spyware%20to%20download%20from%20the%20CLUAS.com%20site.%20Nor%20can%20you%20doctor%20the%20URLs%20to%20create%20a%20customised%20page%20on%20CLUAS.com.
%20![]()
%20Securely%20yours,
%20Eoghan%20O'Neill%20(email:%20editor@cluas.com)
%20Editor%20and%20Webmaster
%20www.CLUAS.com%20-%20lending%20an%20ear%20to%20the%20Irish%20music%20scene
%20">
test